PRIVACY NOTICE - Revised as of 13 December 2021
PERSONAL DATA PROTECTION NOTICE IN LINE WITH PERSONAL DATA PROTECTION ACT 2010
We, Socar Mobility Malaysia Sdn. Bhd. (Registration No. 201701009617 (1223782-T)), and/or any of its subsidiaries, related companies, associates, affiliates, jointly controlled entities, shareholders and any other entities within the group (hereinafter referred to as “SMM”, “Socar”, “we”, “us”, “our” and other similar expressions), value and respect the privacy rights of all our customers across all aspects of our business and we strive to protect your Personal Data in compliance with the laws of Malaysia.
SMM will only collect and use your Personal Data in accordance with the Personal Data Protection Act 2010 (and any other such laws that may be enacted from time to time), with this Privacy Notice and such other term(s) in the agreement(s) that you may contract with us or have contracted with us.
We highly encourage that you carefully read this Privacy Notice to allow you to understand how we collect, use, handle, retain, disclose, and protect your Personal Data.
Succinctly, this Privacy Notice explains:
1. The type of Personal Data that we collect;
2. How we collect your Personal Data;
3. The purposes for which we collect your Personal Data;
4. How we use your Personal Data;
5. The parties that we may disclose your Personal Data to; and
6. The choices that we offer for you to access and update your Personal Data. Kindly take note that unless stated otherwise, the words used herein shall have the same meaning and definition as in the Personal Data Protection Act 2010 (hereinafter referred to as “PDPA”) and the Socar Terms and Conditions
The Personal Data That We Collect
In order to set up your account in all our platforms which includes Socar, TREVO and DASH (“Platforms”) and provide you with the service(s) via the mobile application and/or the website, deal with your inquiry(ies), open and operate an account with us, and/or to inform you of current and upcoming promotion(s), we need to collect and use your Personal Data or. In the event that we are not provided with all the Personal Data that we request, we may not be able to provide you with our service(s) or continue to provide you with our service(s). For the avoidance of doubt, by providing your personal data in any of our Platform, you hereby agree to set up your account in all our Platforms.
The extent and type of Personal Data that we collect from you or any third party depends on our service(s) that you subscribe to and/or the purpose of the collection of the Personal Data. Some of the Personal Data that we collect may be sensitive in nature. The Personal Data that we collect may include, but not limited to, your name, NRIC number, nationality, passport number, address, email address, mobile phone number, date of birth, gender, race, photograph, parking habits and lifestyle choices, motor vehicle registration number, your location, credit card details, and/or debit card details, background information (including financial and criminal records) as applicable We collect this information only with your consent and/or in strict compliance with applicable laws. If you are a company, we may collect such data including, but not limited to,
your company registration number, your phone and/or fax number, your business and/or registered address, and/or your employee’s Personal Data. Companies shall obtain the consent of the employees before providing us with the employees Personal Data
How We Collect Your Personal Data
We will collect your Personal Data that you have provided to us (whether through the Application, the Website, or a physical form), or any other similar forms and/or any information about you that has been or may be collected, stored, used and processed by SOCAR from time to time and includes sensitive Personal Data such as data relating to any commission or alleged commission of offence.
The provision of your Personal Data is voluntary. However, if you do not provide SOCAR your Personal Data, your request for the Application may be incomplete and SOCAR will not be able to process your Personal Data for the Purposes outlined below and may cause SOCAR to be unable to allow you to use SOCAR service.
We may also collect your data from third party related application(s) or software(s) for the purpose of providing you with our services or related services. We may also collect your Personal Data from your employer where the services we provide are related to your employer-employee relationship and we may collect your Personal Data from your employees. We may also obtain your Personal Data from third parties (including but not limited to, information from your referees, public records, or background check agencies who may be engaged to provide us with your Personal Data, including information regarding past criminal record(s), if any). All such information will be kept strictly confidential and used strictly for due diligence and background checks purposes only. In addition to the above, we may also collect your Personal Data from any third-party that you have authorized to disclose your Personal Data to us.
The Purpose of The Collection of Your Personal Data
We collect your Personal Data for the following purposes:
1. to identify users of our service, potential users and their representatives;
2. to provide our services;
3. to offer or provide related services, including our own value-add services or services of our business / strategic partners with whom we may collaborate with (such as for offering or provision of motor insurance services);
4. to manage and maintain your account with us;
5. for administration purpose(s);
6. to develop and/or implement initiatives to improve our services;
7. to seek your opinions or comments about our services;
8. to inform you about promotions, offers and/or other benefits (including third party benefits) that may become available, or to send you alerts, updates, newsletters, marketing and/or promotional materials, including from third parties (such as our subsidiaries, related companies, associates, affiliates, jointly controlled entities, shareholders and any other entities within the group, business / strategic partners), whether by SMS, phone call, email, fax, mail, social media and/or any other appropriate communication channels, which may be of interest to you;
9. to carry out our management, administrative, quality assurance and complaint handling activities in a professional and efficient manner;
10. conduct consumer and market research;
11. to follow up or pursue any queries you make;
12. to conduct due diligence and background checks (including financial and criminal records check), or to carry out any other monitoring or screening activities or risk management procedures that may be required by law or that may have been put in place by us;
13. for credit evaluation purposes including Central Credit Reference Information System (CCRIS) checks;
14. To detect the location of the vehicle for safety and security purposes;
15. for any other purpose(s) related thereto; and
16. for any purpose(s) required or permitted by any law, regulations, guidelines, and/or relevant regulatory authorities.
Use and Disclosure of Personal Data
We shall use and disclose your Personal Data for such purpose(s) that the Personal Data was collected, as indicated above and for any other secondary purpose(s).
We may disclose your Personal Data to our subsidiaries, related companies, associates, affiliates, jointly controlled entities, shareholders and any other entities within the group, business / strategic partners (e.g. insurance companies or any other third parties with whom we may collaborate with), landlord(s), service providers, credit reporting agencies and/or contractors, who assists us in providing and/or supplying our product(s) and service(s) or processes Personal Data for or on behalf of us for any of the purposes as stated herein.
We may also disclose your Personal Data to third parties (including but not limited to their advisers / representatives) in connection with any corporate exercises, e.g. any proposed or actual mergers and/or acquisitions, joint venture, investment or funding exercise, asset sale or for any other matter of such nature which relates to us.
Notwithstanding the above, we may be required, as a result of our contractual obligation(s) to you or to any other third-party, to disclose your Personal Data to the landlords of a particular car parking facility that we manage and operate, and to our auditors who shall conduct audits of our business and services.
Except where indicated above, we will not use and/or disclose your Personal Data unless:
1. we have obtained the consent from the individual concerned;
2. the third-party we disclose the Personal Data to are our agent, service provider and/or contractor, in which case we will require them to only use and disclose the Personal Data only for the purpose for which it was provided to them;
3. the third-party is a person involved in a dealing or proposed dealing (including but not limited to a sale) of all or part of our assets and/or business;
4. the third-party is a credit reporting agency, your creditor, banker, financier, and/or credit provider; and
5. the disclosure is permitted, required and/or authorized by or under law.
In addition to the above, we may use your Personal Data to advise and inform you of new product(s), service(s) and/or marketing initiative that we think may be of interest to you. This may include, but not limited to, product and/or service offerings, newsletters and general information about us, or from our subsidiaries, related companies, associates, affiliates, jointly controlled entities, shareholders and any other entities within the group and/or our selected third-parties (including from our business / strategic partners with whom we may collaborate with).
If you prefer not to receive information about such product(s) and service(s) from us, you can contact our Customer Service Officer and request to be removed from the relevant circulation list.
We would like to highlight to you that your act of unsubscribing will not end the transmission of service-related emails from us, such as administrative email alerts in relation to your account settings except where you have terminated your account with us.
You are more than welcome to request to have access to your data within our storage at any time. If you wish to do so, you may at any time, log in into your online account with us at www.socar.my and view your data within our storage.
In the event that such data of yours is not made available to you via your online account or that you are unable to access your Personal Data, kindly contact our Customer Service Officer. Our Customer Service Officer shall do their best to grant you access where possible within twenty-one (21) days from when our Customer Service Officer receives your request. In the event that we are unable to comply with your request within the aforementioned twenty-one (21) days, we shall try out best to comply within thirty-five (35) days from when our Customer Service Officer receives your request.
1. the identity of the data subject is unidentifiable from the information given;
2. the access impacts on the privacy of others;
3. the request for access is frivolous or vexatious;
4. the cost incurred is far too great;
5. there are confidential commercial information that may be disclosed in the process;
6. the Personal Data is with another data user and such data user are unable to comply;
7. there are existing or anticipated legal proceedings; or
8. such access can be denied under law or by a law enforcement agency we may not be able to provide you with access to the Personal Data we hold about you. In the event that we deny and/or are unable to comply with your request for access, we will inform you the reason(s) of our denial and/or inability to comply. Please note that in processing your request, we may charge you a reasonable fee as prescribed under the Personal Data Protection (Fees) Regulations 2013 or its amendment from time to time to cover any cost incurred by us.
Quality, Correction, & Deletion
We strive to ensure that your Personal Data with us are accurate, complete and up-to-date at all times. If at any point in time you believe that any of the Personal Data of yours that we hold is inaccurate, incomplete or not up-to-date, you should immediately inform us with the correct, complete and accurate data. We will use all reasonable efforts to correct the data within twenty-one (21) days from when our Customer Service
Officer receives your request for correction. In the event that we are unable to make such correction within the aforementioned twenty-one (21) days, we will inform you of our inability to make such correction within reasonable time as well as the reason as to why we are unable to do so. We shall, however, try out best to comply within thirty-five (35) days from when our Customer Service Officer receives your request for data correction.
Alternatively, you may log into your online account with us at www.socar.my and update your details there as this method of correction would be much more fast and convenient for you. In the event that you are unable to correct your details there or such detail is locked from being altered, kindly contact our Customer Service Officer and our Customer Service Officer shall do their best to make the necessary amendment(s) for you.
If you no longer choose to use our services and would like to withdraw your consent from SOCAR to process your Personal Data, kindly contact us at email@example.com. We shall take the necessary steps to erase, destroy, anonymise or prevent access or use of such Personal Data for any purpose other than compliance with this Notice, or for purposes of safety, security, fraud prevention and detection, in accordance with the requirements of applicable laws.
How We Store Your Personal Data
As we strive to protect your Personal Data, we limit the personnel that can access your data and the amount of data accessible by them. Only personnel that specifically requires your Personal Data may access it to carry out their business responsibilities. Our employees are at all times obliged to respect the confidentiality of any Personal Data held by us.
We take reasonable steps to keep your Personal Data secure and protect it from loss, misuse, or unauthorized alteration. Any of the Personal Data you electronically provide to us are stored on secure servers. We also maintain a reasonable physical security procedure to manage and protect the use and storage of records containing Personal Data
WEBSITE, APPLICATION & COOKIES
Changes to Our Privacy Notice
We may update or change this Privacy Notice at any time, from time to time as and w hen we find it necessary to do so. When we do so, we will publish the updated Privacy Notice on our website which shall supersede the previous version of the Privacy No tice. The updated Privacy Notice will apply between us whether or not we have given you specific notice of any change.
We are committed to constantly improve our procedures to ensure that Personal Data that we process are kept secured and treated appropriately. If you feel that we have failed to deal with your Personal Data in accordance with this Privacy Notice, please speak to us so that we have an opportunity to resolve the issue to your satisfaction.
We will log your complaint and our Customer Service Officer will:
1. listen to your concerns and grievances;
2. discuss with you the ways in which we can remedy the situation; and
3. put in place an action plan to resolve your complaint and improve our Personal Data handling procedures if appropriate.
Disclosure to Overseas Recipients
We may process, store and/or transfer your Personal Data to a country located outside of Malaysia, for one or more of the above Purposes or such other purposes as provided in this Privacy Notice. In doing so, we will comply with the PDPA and all other applicable data protection laws.
This Privacy Notice is prepared in English and Bahasa Malaysia. In the event of any discrepancies between the English and Bahasa Malaysia versions of this Privacy Not ice, the English version shall prevail.
If you have any queries about this Privacy Notice or require any further details in relation to your Personal Data, please contact us at firstname.lastname@example.org.